LegalAkashik AI Private LimitedEffective 4 September 2026

The terms this work runs on

Webzero is operated by Akashik AI Private Limited, a company incorporated in India. Webzero was formerly known as Bridge AI. These documents govern this website, the Webzero console and any engagement, and they are written to be read rather than to be survived.

What we collect, why, and what you can demand of us.

Akashik AI Private Limited ("Webzero", "we") is the data fiduciary under India's Digital Personal Data Protection Act, 2023, and the controller under the UK and EU GDPR, for personal data we collect through this website and the Webzero console. Where we process personal data on behalf of a client under an engagement, that client is the controller or data fiduciary and we act as a processor or data processor on their written instructions.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use client engagement data to train models.

1. Who we are

Akashik AI Private Limited, a private limited company incorporated under the Companies Act, 2013 in India, trading as Webzero and formerly known as Bridge AI. Our registered office address is available on request and on our filings with the Ministry of Corporate Affairs. Privacy contact: privacy@webzero.ai.

2. What we collect

Website visitors: pages requested, referring URL, approximate location derived from IP address, browser and device characteristics, and the date and time of the request. This is collected in server and security logs and is used to keep the site available and to defend it.

People who contact us: the category you select, the message you write, and the email address you choose to give. The email field is optional and the form works without it, in which case we cannot reply.

Console users: the username issued to you, an authentication credential, the actions you take in the console and the times you take them. Console access is issued to named individuals at client organisations, not to the public.

Engagement data: run trajectories, request and response metadata, token and cost telemetry, screenshots and logs produced while our benchmark agents attempt journeys on a client-nominated permitted environment. Journeys are attempted with synthetic identities and test instruments. We do not ask for, and our method does not require, production credentials or real customer records.

We do not knowingly collect special or sensitive category personal data, and we ask clients not to place any in a permitted environment. If sensitive personal data reaches us incidentally, we delete it on discovery and record the deletion.

3. Why we process it, and on what basis

To provide and secure this website and the console: our legitimate interests in operating a secure service, and performance of a contract where you are a client user. Under the DPDP Act, processing for these purposes rests on the certain legitimate uses and on the consent you give when you submit information to us.

To answer enquiries and provide the services you engage us for: performance of a contract, or steps taken at your request before entering one.

To improve our benchmark methodology and task library: our legitimate interests, using aggregated or de-identified engagement data only. We do not use client engagement data to train models, and we do not publish client scores, journeys or trajectories, including on this site.

To comply with law, to establish or defend legal claims, and to enforce our terms: compliance with a legal obligation and our legitimate interests.

Where we rely on consent, you may withdraw it at any time by writing to privacy@webzero.ai. Withdrawal does not affect processing already carried out lawfully.

4. Who we disclose it to

Subprocessors who host, secure, support and communicate on our behalf, each under a written agreement described in the subprocessor section below.

Our client, where we produce a report about their property under an engagement. Reports describe surfaces, journeys and failures, not the individuals who built them.

Professional advisers, insurers, auditors and prospective acquirers under confidentiality obligations, and courts, regulators or law enforcement where we are legally compelled. We will resist over-broad requests and, unless prohibited, tell the affected client before disclosing their data.

We do not sell personal data, we do not share it for cross-context behavioural advertising or targeted advertising, and we do not process it for profiling that produces legal effects for an individual.

5. International transfers

We are based in India and use infrastructure that may process data in India, the European Economic Area, the United Kingdom, Singapore and the United States. Where personal data leaves the UK or EEA we rely on an adequacy decision where one applies, and otherwise on the European Commission Standard Contractual Clauses or the UK International Data Transfer Addendum, together with a transfer risk assessment and technical measures including encryption in transit and at rest.

Where the DPDP Act applies, we transfer personal data only to countries not restricted by the Central Government, and we remain accountable for it.

A client may require in its engagement that its data be processed in a named region. We will honour that or decline the work.

6. How long we keep it

Security and server logs: up to 12 months. Contact form submissions: up to 24 months from the last exchange, so that we can pick up a conversation and evidence what was agreed. Console records: for the term of the engagement plus 12 months. Engagement data including trajectories: for the term plus 12 months, or a shorter period if the engagement says so, after which it is deleted or irreversibly de-identified. Records we must keep for tax, accounting or limitation purposes: up to 8 years.

On written request we will delete engagement data earlier, except where we must retain it by law or to defend a live claim.

7. Your rights

Under the DPDP Act, 2023 you may ask for access to a summary of your personal data and our processing, correction, completion, updating or erasure of it, nominate another individual to exercise your rights in the event of death or incapacity, and raise a grievance with us before approaching the Data Protection Board of India.

Under the UK and EU GDPR you may ask for access, rectification, erasure, restriction of processing and portability, object to processing based on legitimate interests, withdraw consent, and complain to a supervisory authority.

If you are a resident of a US state with a comprehensive privacy law, you may ask to know, correct, delete and obtain a copy of your personal data, and opt out of sale, targeted advertising and profiling. We do not carry out any of those three activities. We will not discriminate against you for exercising a right.

To exercise any right, write to privacy@webzero.ai. We may ask for information to verify who you are, and we will not use that information for anything else. We respond within 30 days and will tell you if we need longer.

8. Security

We encrypt data in transit and at rest, restrict access on a least-privilege and need-to-know basis with multi-factor authentication, log administrative access, segregate client engagement data, review vendors before we engage them, and train our people. No system is perfectly secure and we do not claim otherwise. Where a personal data breach is likely to cause harm we will notify affected clients without undue delay and regulators within the periods the applicable law requires, including 72 hours under the GDPR.

9. Children

Our website and services are directed at organisations, not individuals under 18. We do not knowingly process the personal data of a child, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, write to privacy@webzero.ai and we will delete it.

10. Automated decisions

The Webzero score and the reports we produce describe digital infrastructure. They are not decisions about individuals, they are not used for credit, employment, insurance or eligibility decisions about any person, and we do not carry out automated decision-making that produces legal effects for an individual.

11. Changes to this policy

We will update this policy when our processing changes, and the effective date at the top will change with it. Where a change materially affects your rights we will give notice by email to clients and by a notice on this page for at least 30 days before it takes effect. Continued use after that date is acceptance.

Grievance officer

For any complaint about how we handle personal data, including a request under the DPDP Act, write to the Grievance Officer, Akashik AI Private Limited, atprivacy@webzero.ai. We acknowledge within 5 business days and respond substantively within 30 days. If you are in the EU or UK and remain unsatisfied, you may complain to your supervisory authority. If you are in India, you may escalate to the Data Protection Board of India.

What this site is, and what it is not.

By accessing webzero.ai or the Webzero console you agree to these terms. If you do not agree, do not use them. Where a signed agreement, order form or statement of work exists between you and Akashik AI Private Limited, that document prevails over these terms for the services it covers.

1. Who may use this site

You must be at least 18 and, if you act for an organisation, authorised to bind it. You are responsible for anything done through your credentials and must tell us immediately at security@webzero.ai if you believe they have been compromised.

2. The site is information, not advice

Everything on webzero.ai is provided for general information about our services. It is not legal, regulatory, compliance, security, financial or investment advice, and no part of it creates a professional or fiduciary relationship. Figures shown in demonstrations, consoles, sample reports and simulations on this site are illustrative and do not describe any identified client or property.

3. Engagements are governed separately

Services are delivered only under a signed order form, statement of work or master services agreement. Where such a document conflicts with these terms, that document prevails for the services it covers. Nothing on this site is an offer capable of acceptance, a commitment to deliver, or a warranty of any result.

4. What we do not promise

We do not warrant that a score will rise, that an agent will complete a journey, that a finding is exhaustive, or that your property will satisfy any law, regulation, standard or third-party requirement. Readiness is measured against our task library and instrument at a point in time, and a property changes after we measure it.

Our methodology deliberately withholds a score where evidence is thin. An absent finding is not a statement that a risk does not exist.

5. Intellectual property

The Webzero name and the Bridge AI name, the marks, the site, the console, the scoring model, weightings, task library, benchmark fleet, reports and all related intellectual property are owned by Akashik AI Private Limited or its licensors. We grant you a limited, revocable, non-exclusive, non-transferable licence to view this site and, where you are a client, to use the deliverables internally for your own business purposes.

You may not copy, scrape, frame, resell, sublicense, reverse engineer or create derivative works from the site, the console, the scoring model or the task library, or use any of it to build a competing benchmark or to train a model, except to the extent that restriction is unenforceable by law.

You keep ownership of your own property, content and data. You grant us only the licence we need to perform the engagement and, in aggregated or de-identified form, to improve our methodology.

6. Publishing a score

A client may publish its own Webzero score once a run meets our evidence threshold, provided it states the date, the journeys measured and the instrument version, and does not present a journey-level score as a property-level score or imply certification, endorsement or regulatory approval. We may require correction or withdrawal of a materially misleading statement. We do not publish client scores, journeys or trajectories ourselves.

7. Your content and feedback

You are responsible for what you send us and must not send anything unlawful, infringing, malicious or subject to a confidentiality obligation you cannot satisfy. If you give us feedback or suggestions, you grant us a perpetual, irrevocable, royalty-free licence to use them without obligation or attribution.

8. Third-party links

Where we link to a third party we do not control or endorse it and we accept no responsibility for its content, terms or handling of your data.

9. Disclaimer

To the maximum extent permitted by law, this site and the console are provided as is and as available, without warranty of any kind, express or implied, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, uninterrupted availability or freedom from error or malicious code.

10. Limitation of liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, punitive or consequential loss, or for loss of profit, revenue, anticipated savings, goodwill, business opportunity or data, however caused, even if advised of the possibility.

Our total aggregate liability arising out of or in connection with the site, the console and any engagement, whether in contract, tort including negligence, statute or otherwise, is limited to the fees you actually paid us in the 12 months before the event giving rise to the claim, or, where you are a website visitor who has paid us nothing, to INR 10,000.

Nothing in these terms excludes liability that cannot lawfully be excluded, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for wilful misconduct.

11. Indemnity

You will indemnify and hold harmless Akashik AI Private Limited, its officers, employees and contractors against any claim, loss, liability, cost and reasonable legal fee arising from your breach of these terms, your breach of the acceptable use or agent access policies, your unauthorised instruction to run against a property you do not own or lack written authority to test, or your unlawful use of a deliverable.

12. Suspension and termination

We may suspend or withdraw access to the site or the console at any time, with or without notice, where we reasonably believe these terms or either policy has been breached, where security requires it, or where we are legally obliged to. Clauses on intellectual property, disclaimers, liability, indemnity, confidentiality and governing law survive termination.

13. Force majeure

Neither party is liable for a failure to perform caused by an event beyond its reasonable control, including act of God, war, civil unrest, epidemic, act of government, failure of a public network or utility, or a large-scale failure of an upstream cloud or model provider.

14. Governing law and disputes

These terms and any dispute arising out of them are governed by the laws of India. The parties will first attempt to resolve any dispute by good-faith discussion between senior representatives within 30 days.

Failing that, the dispute will be referred to arbitration under the Arbitration and Conciliation Act, 1996, before a sole arbitrator appointed by agreement, with the seat and venue at Bengaluru, Karnataka, and proceedings in English. The award is final and binding. Nothing prevents either party from seeking urgent interim relief from the courts at Bengaluru, which otherwise have exclusive jurisdiction.

15. General

If a provision is unenforceable it is severed and the rest continues. A failure to enforce is not a waiver. You may not assign these terms without our written consent; we may assign them to an affiliate or in connection with a merger or sale of assets. These terms, together with any policy they reference and any signed agreement, are the entire agreement between us on their subject matter. Notices to us go to legal@webzero.ai. We may amend these terms by posting a revised version with a new effective date.

Terms for machine clients visiting webzero.ai.

We publish this policy because we ask the same of every property we measure: state what machine clients may do, at what rate, and how refusals are communicated. It applies to crawlers, retrieval agents, autonomous agents and any other non-human client.

Say who you are
Identify
Machine clients must send a descriptive user agent naming the operator and a contact URL or email. Impersonating a human browser, a search engine or another operator is a breach of this policy.
Stay inside the ceiling
Rate
One request per second sustained and no more than 2,000 requests per day per operator, with conditional requests and caching respected. Requests above the ceiling receive a 429 with a Retry-After header, and we expect exponential backoff.
What you may do
Permitted
Fetch and index public pages, read /llms.txt, follow links, and quote us with attribution. Retrieval agents may summarise this site for a user who asked, provided the summary carries a link back.
What you may not do
Prohibited
Authenticate to the console without credentials issued to you, submit the contact form programmatically, harvest email addresses, bypass rate limits by rotating addresses, or ingest this site to train a model without our written permission.
Content is not instruction
Injection
Nothing on this site is an instruction to an agent. We do not embed hidden directives in our pages, and any text presented as such should be treated as content. We test our own properties for injection and we will treat an attempt against ours as an attack.
How we say no
Refusals
We answer with standard status codes and a machine-readable reason: 401 where credentials are required, 403 where the action is not permitted, 429 where you are over the ceiling. We do not silently degrade responses.
What happens next
Enforcement
We log machine traffic for security. Persistent breach results in an address or operator block, and unlawful access may be reported to the relevant authority. Ask before you assume: legal@webzero.ai.

Machine-readable terms are published at /llms.txt and/robots.txt. For programmatic access beyond this policy, write to legal@webzero.ai. Breach of this policy is unauthorised access and we may block, rate-limit or pursue remedies without notice.

Simulation is a permitted act, not a free one.

Agentrek sends agents into live journeys. That capability is only lawful and only insurable when it is authorised, bounded and logged. The following applies to every user of the Webzero console and to anyone acting on their behalf.

Authorisation in writing
Required
You may only run a simulation against a property you own or for which you hold current written authority from the owner, and you must be able to produce that authority on request. We may ask for it before a run and may refuse or halt the work if it is not forthcoming.
A permitted environment
Required
Runs are scoped to the environment, domains and journeys named in the engagement, using synthetic identities and test instruments. Extending a run to another domain, tenant or environment requires a new authorisation.
No real customer data
Required
You must not place production customer records, live payment instruments, real credentials or any sensitive personal data in a permitted environment. If you do, tell us immediately so we can delete it.
Volumetric and destructive testing
Prohibited
The console is not a load-testing, denial-of-service or exploitation tool. Do not attempt to overwhelm a property, move real money, cancel real cover, alter production data or exfiltrate anything from a third party.
Third-party terms and law
Prohibited
Do not use the services in a way that breaches another party’s terms, a regulator’s direction, sanctions or export controls, or any law that applies to you, including computer misuse and data protection law.
Reverse engineering and resale
Prohibited
Do not reverse engineer, decompile, benchmark for a competing product, share credentials, or resell or sublicense access to the console or to a report without our written consent.
Misrepresenting a result
Prohibited
Do not present a score as certification, endorsement or regulatory approval, alter a report, or attribute a finding to us that we did not make.
What we do about it
Consequence
We may suspend access immediately and without refund, halt a run mid-flight, notify the affected property, and terminate the engagement for material breach. You remain liable for loss caused by an unauthorised run.

We may suspend access immediately where we reasonably believe this policy has been breached, and we will report unlawful activity to the affected property and to the authorities where we are required to.

The controls a risk committee will ask about.

Our engagement model is the first control: we run against a permitted environment you nominate, with synthetic identities and test instruments. We do not require production credentials and no journey we run touches a live customer record.

Model
Permitted environment only

We run against an environment you nominate, never production, with synthetic identities and test instruments. No journey we run touches a live customer record, and we hold no production credentials.

Access
Least privilege, named humans

Console and infrastructure access is granted to named individuals on a need-to-know basis, protected by multi-factor authentication, reviewed at least quarterly and revoked on the day a role changes.

Data
Encrypted and segregated

Data is encrypted in transit with TLS and at rest, and each client’s engagement data is logically segregated. Trajectories, screenshots and logs are stored with the same controls as the reports built from them.

Logging
Attributable by design

Every run is logged with the agent identity, the mandate it acted under, the actions attempted and what was returned. The same evidence that makes a report reproducible makes our own operations auditable.

Vendors
Reviewed before engagement

Subprocessors are assessed for security, data protection and location before use, bound by written terms no less protective than ours, and re-reviewed on renewal or on a material change.

People
Vetted and trained

Personnel are subject to background verification where lawful, confidentiality obligations that survive their engagement, and security and data protection training on joining and annually after.

Incidents
Detect, contain, tell you

We maintain a documented incident response plan with named owners. On a confirmed incident affecting your data we contain, investigate, and notify you without undue delay with what we know, what we are doing and what we recommend, followed by a written post-incident report.

Continuity
Recoverable

Systems are backed up with restores tested periodically, and our engagements are designed so that a failure at our end delays a report and never affects your production service.

We do not claim certifications we do not hold. Our current attestation status, penetration test summary, data processing addendum and security questionnaire responses are available under NDA: write to security@webzero.ai.

Who else touches the data, and on what terms.

Every subprocessor is engaged under a written agreement with confidentiality, security and data protection obligations no less protective than ours, and processes data only on our instructions. The named list current at the date of your engagement is annexed to the data processing addendum.

Cloud infrastructure and hosting
India · EEA · US
Compute, storage, database and network services that run the website, the console and the simulation fleet, and that store engagement data and logs.
Model and inference providers
EEA · US
Large language model and agent inference services used by the benchmark fleet during a run. Prompts and page content from a permitted environment may be processed by these providers under zero-retention or no-training terms where the provider offers them.
Email and communications
EEA · US
Transactional and business email used to reply to enquiries, deliver reports and issue console credentials.
Error and performance monitoring
EEA · US
Application logging and error reporting used to keep the console available and secure. Configured to minimise personal data and to drop request bodies.
Business systems
India · EEA · US
Document storage, contract execution, accounting and support tooling used to run the company and to administer engagements.

We give clients at least 30 days' written notice before adding or replacing a subprocessor that processes their data, and a client may object on reasonable data protection grounds, in which case we will propose an alternative or the affected service may be terminated without penalty for the unused term.

No advertising cookies, no tracking pixels.

What we set

This website uses strictly necessary storage only: a session cookie where you authenticate, and browser local storage that remembers interface state such as a dismissed banner or your position in a page. There are no advertising cookies, no tracking pixels, no fingerprinting and no cross-site profiling on this site.

Why there is no banner

Consent is required for non-essential cookies. Because we set none, there is nothing to consent to, and we would rather not interrupt you to ask a question with one answer. If we ever introduce analytics or any non-essential cookie, we will ask for consent first, through a banner that lets you refuse as easily as accept, and we will update this notice before the change takes effect.

How to control it

Your browser can block or delete cookies and clear local storage at any time. Blocking strictly necessary storage will prevent console login from working. We honour Global Privacy Control signals, though we have no sale or sharing of personal data to opt out of.

Server logs

Separately from cookies, our servers log requests for security and availability as described in the privacy policy. These logs are not used to build a profile of you and are retained for up to 12 months.

Find something, tell us, and we will not come after you.

Report suspected vulnerabilities tosecurity@webzero.ai with enough detail to reproduce. If you act in good faith and within this policy, we will not pursue or support legal action against you, and we will treat your research as authorised under India's Information Technology Act, 2000 and equivalent computer misuse laws.

In scope

webzero.ai and its subdomains, the Webzero console, and our published machine interfaces. If you are unsure whether an asset is ours, ask before you test it.

Out of scope

Denial of service and volumetric testing, physical attacks, social engineering of our people or vendors, spam or automated scanner output without a demonstrated impact, and anything that accesses, modifies or destroys data belonging to another person. Client properties are never in scope for research, even where we have measured them.

What we ask of you

Report promptly and privately, give us reasonable time to fix before any public disclosure, use only test accounts you control, take no more data than you need to prove the issue, delete what you took once reported, and do not extort. Do not use a finding to access a client environment.

What we commit to

We acknowledge within 5 business days, give you a triage assessment within 10, and aim to remediate a valid high-severity issue within 90 days. We will keep you informed, credit you if you would like to be credited, and will not pursue or support legal action against research conducted in line with this policy. We do not currently run a paid bounty programme, and we will say so plainly rather than imply one.

How to reach us

security@webzero.ai for vulnerabilities, privacy@webzero.ai for data protection, legal@webzero.ai for everything else. Encrypted correspondence is available on request.

Questions from your legal or risk team?

We answer security questionnaires, sign DPAs and NDAs, and will walk your risk committee through the permitted environment model before anything is scoped.